5 ms·
Why did it have to shut down?
by donttrack 8y ago
Why did it have to shut down?
- tankenmate 8y agoUnable and/or unwilling to assess compliance/risk, this leads to the owner wanting to shut down.
- AdamGibbins 8y agoScroll down, it answers the question.
- lucb1e 8y ago(not OP) I scrolled down and didn't find an answer. The section labeled "why shut down" mentions (paragraph by paragraph): - "[GDPR] creates uncertainty and risk" -- which? - "fines of 4% of turnover or €20 million (whichever is higher)" -- as if a small infraction is going to get the maximum punishment. He can't be serious here. - "ambiguously-defined hoops" -- which requirements are ambiguous? - "parasitic no-win-no-fee legal firms, puts website owners at risk of vindictive reporting" -- if you ever needed one of those companies (I did unfortunately), you'd know that someone always ends up paying the lawyers. Either the sued company or the client. It's definitely not risk-free for the client. - "this new EU law hurts small and ethical startups" -- what clause of GDPR would ethical startups run afoul of anyway? It's aimed at unethical ones. And as for "small", then you can't get a big fine anyway right? At least, unless you intentionally cause big damages, I don't see how a small firm like this could unintentionally cause such big damages that large fines are in order. So it's not answered. And I am still wondering what part of GDPR he doesn't already comply with in the website's current form, as the Dutch "WBP" from 2001 required 95% the same things. I assume the UK generally has somewhat similar laws.
- davorak 8y agoSome people are under the impression that ip addresses fall under "personal information". So if the user account is deleted and the associated ip logs are not deleted this would be a GDPR violation. Another potential violation would be asking a users age(like asking their birthday), but not needing their age for the operation of the service. It is currently unclear how rigorously GDPR will be enforced. In the extreme case of rigorous enforcement nearly all current server/frameworks would cause violations by default and would need to be overhauled. There are a bunch of other examples in the comments that are likely violations for the site as well. It is unclear how many of these apply since it is unclear how the GDPR will be enforced.
- jimktrains2 8y ago> Another potential violation would be asking a users age(like asking their birthday), but not needing their age for the operation of the service. In theory, in the US this could be driven by COPPA, but I havn't seen a birthday asked for that reason in a long time. It also wouldn't be a reason to store it, only to ask and process ephemerally. I believe it's also common in the US for alcohol-related websites to ask age, although that could be misguided, it is common. Again, not a reason to store, but to ask.
- davorak 8y agoYeah I was not clear. My intent was to talking about storing of a birthday vs storing a boolean indicating if the user was the age of majority or a boolean for weather they were 13+ for COPPA. Storing the value, rather than ephemerally processing it, is a matter of convenience so you do not have to ask your authenticated user to re-input their age/birthday/<are you an adult> all of the time. That said it seems unlikely that a regulator would come down hard on a data processor that stored a date vs storing a boolean value.